The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. https://pypi.org/project/cryptography/#history https://github.com/pyca/cryptography/compare/41.0.1...41.0.2 https://github.com/pyca/cryptography/issues/9207 https://github.com/pyca/cryptography/pull/9208
Created python-cryptography tracking bugs for this issue: Affects: fedora-all [bug 2231274]
Created ansible-lint tracking bugs for this issue: Affects: fedora-all [bug 2231281] Created cura tracking bugs for this issue: Affects: fedora-all [bug 2231282] Created duplicity tracking bugs for this issue: Affects: fedora-all [bug 2231283] Created pypy tracking bugs for this issue: Affects: fedora-all [bug 2231284] Created pypy3.8 tracking bugs for this issue: Affects: fedora-all [bug 2231285] Created pypy3.9 tracking bugs for this issue: Affects: fedora-all [bug 2231286] Created python-ansible-compat tracking bugs for this issue: Affects: fedora-all [bug 2231288] Created python-cryptography-vectors tracking bugs for this issue: Affects: epel-all [bug 2231276] Created python-docker tracking bugs for this issue: Affects: epel-all [bug 2231277] Created python-molecule tracking bugs for this issue: Affects: fedora-all [bug 2231289] Created python-play-scraper tracking bugs for this issue: Affects: fedora-all [bug 2231290] Created python-types-cryptography tracking bugs for this issue: Affects: fedora-all [bug 2231291] Created python-uvicorn tracking bugs for this issue: Affects: fedora-all [bug 2231292] Created python-yfinance tracking bugs for this issue: Affects: fedora-all [bug 2231293] Created python3-cryptography tracking bugs for this issue: Affects: epel-all [bug 2231278] Created python3-cryptography-vectors tracking bugs for this issue: Affects: epel-all [bug 2231279] Created python3-docker tracking bugs for this issue: Affects: epel-all [bug 2231280]
Created ansible-lint tracking bugs for this issue: Affects: fedora-all [bug 2231299] Created cura tracking bugs for this issue: Affects: fedora-all [bug 2231300] Created duplicity tracking bugs for this issue: Affects: fedora-all [bug 2231302] Created pypy tracking bugs for this issue: Affects: fedora-all [bug 2231303] Created pypy3.8 tracking bugs for this issue: Affects: fedora-all [bug 2231304] Created pypy3.9 tracking bugs for this issue: Affects: fedora-all [bug 2231305] Created python-ansible-compat tracking bugs for this issue: Affects: fedora-all [bug 2231306] Created python-cryptography-vectors tracking bugs for this issue: Affects: epel-all [bug 2231294] Created python-docker tracking bugs for this issue: Affects: epel-all [bug 2231295] Created python-molecule tracking bugs for this issue: Affects: fedora-all [bug 2231307] Created python-play-scraper tracking bugs for this issue: Affects: fedora-all [bug 2231308] Created python-types-cryptography tracking bugs for this issue: Affects: fedora-all [bug 2231309] Created python-uvicorn tracking bugs for this issue: Affects: fedora-all [bug 2231310] Created python-yfinance tracking bugs for this issue: Affects: fedora-all [bug 2231311] Created python3-cryptography tracking bugs for this issue: Affects: epel-all [bug 2231296] Created python3-cryptography-vectors tracking bugs for this issue: Affects: epel-all [bug 2231297] Created python3-docker tracking bugs for this issue: Affects: epel-all [bug 2231298]
The affected code was introduced in upstream release 40.0 and fixed in upstream release 41.0.2. The GH security advisory https://github.com/advisories/GHSA-cf7p-gm2m-833m has the versions wrong. The NIST CVE entry https://nvd.nist.gov/vuln/detail/CVE-2023-38325 has the correct version span. Since releases < 40.0 are not affected by the bug, no released version of Fedora, CentOS Stream, or RHEL are affected. - RHEL 8 has python-cryptography-3.2.1 or lower - RHEL 8's Python 3.8 module has python38-cryptography-2.8 - RHEL 8's Python 3.9 module has python39-cryptography-3.3.1 - RHEL 9 has python-cryptography-36.0.1 or lower - sat-delivery has python-cryptography-38.0.4-1.el8pc / python-cryptography-38.0.4-1.el9pc - since python-cryptography is an AppStream package of RHEL, there shouldn't be any EPEL packages. - Fedora 37 and 38 have python-cryptography-37.0.2 - Fedora 39/Rawhide have python-cryptography-40.0.2, however Fedora 39 is not released yet. It just branched off Rawhide earlier this week. Vipul, could you please verify my findings and then close all tickets except for Fedora 39/Rawhide related tickets? I already have updates for Fedora 39/Rawhide prepared.
For the record, RHEL 7.9 has python-cryptography-1.7.2
sure bud, also that should be closed out in secondary analysis
I have requested an update of the GHA to add an '{"introduced": "40.0.0"}' event, https://github.com/github/advisory-database/pull/2620 . This will also silence false-positives in Quay's Clair.